CVE-2022-2619Improper Encoding or Escaping of Output in Google Chrome

Severity
4.3MEDIUMNVD
EPSS
0.3%
top 49.38%
CISA KEV
Not in KEV
Exploit
No known exploits
Timeline
PublishedAug 12
Latest updateAug 13

Description

Insufficient validation of untrusted input in Settings in Google Chrome prior to 104.0.5112.79 allowed an attacker who convinced a user to install a malicious extension to inject scripts or HTML into a privileged page via a crafted HTML page.

CVSS vector

CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:L/A:NExploitability: 2.8 | Impact: 1.4

Affected Packages6 packages

CVEListV5google/chromeunspecified104.0.5112.79
NVDgoogle/chrome< 104.0.5112.79
debiandebian/chromium< chromium 104.0.5112.79-1 (bookworm)
Debianchromium/chromium< 104.0.5112.79-1~deb11u1+3

Also affects: Fedora 37

🔴Vulnerability Details

2
GHSA
GHSA-7jm8-q7ph-7v6r: Insufficient validation of untrusted input in Settings in Google Chrome prior to 1042022-08-13
OSV
CVE-2022-2619: Insufficient validation of untrusted input in Settings in Google Chrome prior to 1042022-08-12

📋Vendor Advisories

3
Microsoft
Chromium: CVE-2022-2619 Insufficient validation of untrusted input in Settings2022-08-09
Chrome
Stable Channel Update for Desktop: CVE-2022-26182022-08-02
Debian
CVE-2022-2619: chromium - Insufficient validation of untrusted input in Settings in Google Chrome prior to...2022